Vulnerabilities
Vulnerable Software
Misp-Project:  >> Misp  >> 2.3.0  Security Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) add.ctp, (2) edit.ctp, and (3) ajaxification.js.
CVSS Score
6.1
EPSS Score
0.013
Published
2016-09-03
app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.
CVSS Score
9.8
EPSS Score
0.023
Published
2016-09-03


Contact Us

Shodan ® - All rights reserved